MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9705b02f24c62bc938211d125bfeb3c4fc842b2cd74f05df36cfb3a23c7bbcec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



HijackLoader


Vendor detections: 13


Intelligence 13 IOCs YARA 6 File information Comments

SHA256 hash: 9705b02f24c62bc938211d125bfeb3c4fc842b2cd74f05df36cfb3a23c7bbcec
SHA3-384 hash: 3b1edd8da90dd9260615a63c54b0780d2748d0f10bd25e36a71f77642e194c80940faa33ff714b062e4941164567e9bd
SHA1 hash: 9c69c37c001725692b5fae5f607d81d00861f4c1
MD5 hash: a521a15ceefeca3733a5cfa4467687a2
humanhash: august-shade-eleven-zulu
File name:vn.vbs
Download: download sample
Signature HijackLoader
File size:1'737 bytes
First seen:2025-10-28 22:03:19 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 24:JzIAW/zPtUuXpk563gNApQ3b/iMB0SIdQrIrKViKk5LDwbjmVfJZ8Q/+isB7MTqE:+AKOJbNAGzN/fIUijfJVJ9/+dSiru
Threatray 510 similar samples on MalwareBazaar
TLSH T13831125F3D1BC250A332A624457E450ED6C1941B26038C41B59CD88EFFB966AEEB43EB
Magika vba
Reporter juroots
Tags:HIjackLoader vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
CH CH
Vendor Threat Intelligence
Verdict:
Malicious
Score:
91.7%
Tags:
virus agent spawn
Verdict:
Malicious
File Type:
vbs
First seen:
2025-10-28T12:17:00Z UTC
Last seen:
2025-10-28T18:07:00Z UTC
Hits:
~100
Detections:
Trojan.JS.SAgent.sb Trojan-Downloader.VBS.SLoad.sb Trojan-Downloader.JS.SLoad.sb Trojan.Win64.SBEscape.sb Trojan.Win32.Strab.sb Trojan.Win32.Penguish.sb Trojan.Win32.Crypt.sb
Verdict:
Malware
YARA:
1 match(es)
Tags:
ADODB.Stream MSXML2.XMLHTTP Scripting.FileSystemObject VBScript WScript.Shell
Threat name:
Script-WScript.Hacktool.SuspClickfix
Status:
Malicious
First seen:
2025-10-28 18:28:10 UTC
File Type:
Text (VBS)
AV detection:
6 of 24 (25.00%)
Threat level:
  1/5
Result
Malware family:
hijackloader
Score:
  10/10
Tags:
family:hijackloader discovery loader
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Windows directory
Suspicious use of SetThreadContext
Enumerates connected drives
Checks computer location settings
Deletes itself
Executes dropped EXE
Loads dropped DLL
Badlisted process makes network request
Detects HijackLoader (aka IDAT Loader)
HijackLoader
Hijackloader family
Malware family:
IDATLoader
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:malware_shellcode_hash
Author:JPCERT/CC Incident Response Group
Description:detect shellcode api hash value
Rule name:Windows_Trojan_GhostPulse_caea316b
Author:Elastic Security

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

HijackLoader

Visual Basic Script (vbs) vbs 9705b02f24c62bc938211d125bfeb3c4fc842b2cd74f05df36cfb3a23c7bbcec

(this sample)

  
Delivery method
Distributed via web download

Comments